WordPress Plugin Vulnerabilities
Under Construction, Coming Soon & Maintenance Mode < 1.1.2 - Reflected Cross-Site Scripting (XSS)
Description
The includes/mc-get_lists.php file decoded JSON data fetched from the URL provided and then displayed the HTML from the response without any HTML escaping, leading to a reflected cross-site scripting issue where the payload is on a different server (controlled by the attacker for example).
The issue is exploitable via direct access to the affected file, and ucmm_mc_api AJAX call (available to both authenticated and unauthenticated users).
Proof of Concept
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Mr.F
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2021-02-27 (about 5 years ago)
Added
2021-02-27 (about 5 years ago)
Last Updated
2021-03-01 (about 5 years ago)